CVE-2016-6341
MEDIUMoVirt Engine <4.0.3 - Info Disclosure
Title source: llmDescription
oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files.
Scores
CVSS v3
5.5
EPSS
0.0006
EPSS Percentile
20.0%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-200
Status
published
Affected Products (2)
ovirt/ovirt
< 4.0.2
n/a/n/a
Timeline
Published
Apr 20, 2017
Tracked Since
Feb 18, 2026